#bumsrakete — Public Fediverse posts
Live and recent posts from across the Fediverse tagged #bumsrakete, aggregated by home.social.
-
#FreeBSD: Rechteausweitungslücke mit augenzwinkerndem Codenamen | Security https://www.heise.de/news/FreeBSD-Rechteausweitungsluecke-mit-augenzwinkerndem-Codenamen-11328722.html #Patchday #Bumsrakete
-
Also, notable mention. unexpected thread: https://github.com/lenucksi/aur-malware-check/issues/5
Are there any plans on some bit more central validation, maybe even with some AI/LLM/... with regular conversion of insights to fixed/deterministic rules as discussed throughout the thread? Something something semgrep/opengrep, yara, flathub manifest style etc pp?
Update: Looping in @archlinux here.
Also, any plans on enforcing this -> https://wiki.archlinux.org/title/DeveloperWiki:Building_in_a_clean_chroot for all the AUR build business?Also: How does this incident not yet have a creative name? I'm not asking for a #bumsrakete but there's gotta be something 🤣
Edit: https://jguer.space/blog/2026-06-15-yay-v13 delivered. It's the #AURpocalypse 😱 🤣
#llm #flathub #abuseprevention #malwareCheck #yara #opengrep #archLinux #archlinuxaur #aur #AURpocalypse
-
BUMSRAKETE™ — The Most Beautiful, Most Tremendous FreeBSD Vulnerability In The History Of Computing. BELIEVE ME.
-
> The CVSS people, very sad people, sometimes the worst people, capped severity at 10.0. We had to invent a new scale because this bug demanded it. Tremendous demand. 13/10. Nobody knew kernel bugs could be this big. Many such cases.
-
So, there is a (now patched) FreeBSD kernel bug with privilege escalation, and... someone had a *lot* of fun setting up a page for it. 🤭
-
-
Das nenne ich mal einen Bug-Report… oder eine Bug-Website… oder ach keine Ahnung 😂 #freebsd #bumsrakete
-
"BUMSRAKETE™
The HUGEST, the MOST TREMENDOUS FreeBSD page-cache write primitive in the history of computing."
-
Nice, #Bumsrakete works on a #FreeBSD 15.0 system.
TL;DR page cache #vuln in the #kernel, exploitable within seconds, privesc from normal user to #root
17/10 can recommend ⭐🌟
-
Bumsrakete being delivered to the corporate infosec world
-
TIL: Die Domain bumsrakete.de ist noch frei.
-
Mein Highliht des Tages: #Bumsrakete https://bumsrake.de/ - also die Seite. Die Lücke ist nicht so lustig. #FreeBSD #ITsec
-
#Linux got bitten by crypto-related page cache vulnerabilities in recent weeks. They had rather boring names: #CopyFail #DirtyFrag #Fragnesia
The #FreeBSD community is fixing this by naming their own bug of this class #BUMSRAKETE.
(Now, if you ran the name through a translator and are questioning its legitimacy: It's as real as the person that inspired the bug report's style, unfortunately.)
-
The #infosec knee jerk reaction to https://bumsrake.de appears to be:
"Wait are they having FUN with vulnerability disclosure? Not on my watch!"If you want your vulnerability details in a boring format feel free to buy a TI feed. Don't tell researchers who invested a ton of their time how to disclose stuff.
-
Dirty Pipe FreeBSD "Bumsrakete": https://bumsrake.de or https://www.freebsd.org/security/advisories/FreeBSD-SA-26:26.ktls.asc
CVSS 13 of 10 😂 Cant stop laughing 🙈😁